2025 API Blindspots and Breakthroughs: How CISOs Are Approaching API Risk Survey Report

See how 300 CISOs are tackling API discovery, auditing, and security in an API-first world.

  • 17% of CISOs have a fully developed API security strategy in place
  • 19% have complete visibility into all APIs across their organization
  • 90% can’t confirm they’re free of unknown or unmanaged APIs
  • Most companies audit APIs every 4–12 weeks, leaving critical visibility gaps
  • 76% of CISOs still rely on legacy tools like WAFs and gateways for API security

As APIs power everything from customer experiences to AI-driven workflows, security leaders face mounting pressure to secure an expanding and often invisible attack surface.

The findings offer a peer-driven look at where organizations are today and how API security strategies are beginning to evolve.

Download the report and get the survey results.

Salt Security is committed to protecting and respecting your privacy, and we’ll only use your personal information to administer your account and to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to being contacted for these purposes, please tick one or more boxes above.

You can unsubscribe from these communications at any time. For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our privacy policy. By submitting this form, you consent to allow Salt Security to store and process the personal information submitted above to provide you the content requested.